StackRadar

CVE-2026-18374

Medium

Advisory

Published 27 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.9
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,723
of 17,832 indexed, latest versions
Container images
2,750
deployed by those charts
Fix available
2 of 5
affected packages

CVE-2026-18374 affecting package glibc 2.38-21

Carried by container images the latest versions of 2,723 of 17,832 indexed charts deploy, on 2,750 images.

Affected packageAffected versionsFixed inImages
glibcdeb2.23-0ubuntu5, 2.23-0ubuntu7, 2.23-0ubuntu9, 2.23-0ubuntu10+66 more2.41-12+deb13u3+e72,695
eglibcdeb2.19-0ubuntu6.3, 2.19-0ubuntu6.6, 2.19-0ubuntu6.13, 2.19-0ubuntu6.14+1 moreno fix listed7
glibc-2.44apk2.44-r1, 2.44-r4, 2.44-r52.44-r634
glibcrpm2.38-16.azl3, 2.38-18.azl3, 2.38-20.azl3no fix listed13
glibc-2.43apk2.43-r14no fix listed1
OSV records
DEBIAN-CVE-2026-18374UBUNTU-CVE-2026-18374AZL-98042CGA-27g8-4xhq-hhr3CGA-2w63-hvq4-f4pcECHO-9169-1fd9-0c1c
Also known as
CGA-3qmp-39qm-cjf8, CGA-3xw7-x4r7-x678, CGA-5g65-xm2q-rjhf, CGA-5wh2-vg99-j76x, CGA-63j2-v7q6-8x84, CGA-6rf5-rrq5-7pff, CGA-772j-3386-6g56, CGA-79v3-g2j9-ffq2, CGA-8hxc-pvg5-xr9j, CGA-c62g-2q4h-pjjg, CGA-f52m-j726-w2p6, CGA-h33h-m88h-4gc6, CGA-m923-g68q-v4rq, CGA-m9qj-fr43-382g, CGA-mm85-9c9x-q266, CGA-v3jf-jvqj-vgxj, CGA-x2q5-w2xg-rgqc, CGA-x3rq-r7j3-jgpx

Charts affected

2,723 by stars
ChartLatestAffected imagesRadar Score
argo-cdargoOfficialVerified publisher10.9.21 of 3See more

argo-cd argo 10.9.2

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
glibc@2.43-2ubuntu2.4
no fix listed

Open the chart page →

3,085
kubernetes-dashboardk8s-dashboard7.14.01 of 5See more

kubernetes-dashboard k8s-dashboard 7.14.0

1 of the 5 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/kong:3.912972ce1ab63
glibc@2.39-0ubuntu8.9
no fix listed

Open the chart page →

3,197
gitlabgitlabVerified publisher10.4.010 of 21See more

gitlab gitlab 10.4.0

10 of the 21 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
envoyproxy/gateway:v1.9.10049bcb384c5
glibc@2.41-12+deb13u3
no fix listed
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.01c38ad710b0c
glibc@2.41-12+deb13u3
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.0704cd68566af
glibc@2.41-12+deb13u3
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.0696d798a5c85
glibc@2.41-12+deb13u3
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabdc1a8972c640
glibc@2.36-9+deb12u14
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.26645e014f75d
glibc@2.41-12+deb13u4
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitlab-kas:v19.4.08ae8be4645ce
glibc@2.41-12+deb13u4
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3aca1bb3d5b7e
glibc@2.41-12+deb13u3
no fix listed
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
glibc@2.41-12+deb13u3
no fix listed
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

16,518
jenkinsjenkinsciOfficialVerified publisher5.9.631 of 2See more

jenkins jenkinsci 5.9.63

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
jenkins/jenkins:2.568.3-jdk21c1e4c349365f
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

2,585
ciliumciliumOfficialVerified publisher1.20.22 of 3See more

cilium cilium 1.20.2

2 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.22939231d0d3e
glibc@2.43-2ubuntu2.4
no fix listed
quay.io/cilium/cilium-envoy:v1.37.6-1789133542-cbec91f666af0bf742da986d43832932dbb26b82af7382699576
glibc@2.39-0ubuntu8.9
no fix listed

Open the chart page →

1,072
airflowapache-airflowOfficialVerified publisher1.22.01 of 4See more

airflow apache-airflow 1.22.0

1 of the 4 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/redis:7.2-bookworm0637954999d0
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

3,193
velerovmware-tanzu12.2.01 of 1See more

velero vmware-tanzu 12.2.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
velero/velero:v1.18.237396519f399
glibc@2.35-0ubuntu3.13
no fix listed

Open the chart page →

1,100
nextcloudnextcloud9.3.01 of 1See more

nextcloud nextcloud 9.3.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/nextcloud:34.0.4-apachea5ace30c695a
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

3,962
giteagiteaOfficialVerified publisher12.7.03 of 4See more

gitea gitea 12.7.0

3 of the 4 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
glibc@2.36-9+deb12u10
no fix listed
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
glibc@2.36-9+deb12u10
no fix listed
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

8,989
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
glibc@2.35-0ubuntu3.1
no fix listed

Open the chart page →

6,761
authentikgoauthentikOfficialVerified publisher2026.8.31 of 1See more

authentik goauthentik 2026.8.3

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.8.3ab9b4e8cc4ab
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

997
nginx-ingressnginxVerified publisher2.7.31 of 1See more

nginx-ingress nginx 2.7.3

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
nginx/nginx-ingress:5.6.33e97f06dce1c
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

1,140
artifact-hubartifact-hubVerified publisher1.23.02 of 7See more

artifact-hub artifact-hub 1.23.0

2 of the 7 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
glibc@2.41-12
no fix listed
artifacthub/tracker:v1.23.05368d21a6e5c
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

11,038
alloygrafana1.12.11 of 2See more

alloy grafana 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
grafana/alloy:v1.19.2b8ec653c4423
glibc@2.39-0ubuntu8.8
no fix listed

Open the chart page →

1,214
argo-cdargo-cd-oci10.9.21 of 3See more

argo-cd argo-cd-oci 10.9.2

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
glibc@2.43-2ubuntu2.4
no fix listed

Open the chart page →

3,085
jupyterhubjupyterhubOfficialVerified publisher4.4.22 of 7See more

jupyterhub jupyterhub 4.4.2

2 of the 7 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.4.2108fbb01c3fe
glibc@2.36-9+deb12u14
no fix listed
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

8,324
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

30,706
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
glibc@2.36-9+deb12u4
no fix listed

Open the chart page →

11,466
falcofalcosecurity9.2.01 of 3See more

falco falcosecurity 9.2.0

1 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.45.0d7d287d4dcee
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

3,027
kongkongOfficialVerified publisher3.4.11 of 2See more

kong kong 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/kong:3.912972ce1ab63
glibc@2.39-0ubuntu8.9
no fix listed

Open the chart page →

867
openebsopenebsOfficialVerified publisher4.6.12 of 35See more

openebs openebs 4.6.1

2 of the 35 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
glibc@2.39-0ubuntu8.4
no fix listed
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

24,385
jiraatlassian-data-centerVerified publisher2.0.151 of 2See more

jira atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
atlassian/jira-software:11.3.11e5548cd4eea8
glibc@2.39-0ubuntu8.8
no fix listed

Open the chart page →

1,677
mlflowcommunity-chartsVerified publisher1.11.71 of 1See more

mlflow community-charts 1.11.7

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
burakince/mlflow:3.16.0ab4b566644b9
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

666
qdrantqdrantOfficialVerified publisher1.19.11 of 1See more

qdrant qdrant 1.19.1

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.19.112364fe851b9
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

858
vectorvectorVerified publisher0.58.01 of 1See more

vector vector 0.58.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
timberio/vector:0.58.0-distroless-libc6c93dfe2554c
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

360
apisixapisix2.17.02 of 3See more

apisix apisix 2.17.0

2 of the 3 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
apache/apisix:3.18.0-ubuntu9ee5df1611f9
glibc@2.39-0ubuntu8.8
no fix listed
bitnamilegacy/etcd:latest99b408c15272
glibc@2.36-9+deb12u10
no fix listed

Open the chart page →

3,200
dagsterdagsterVerified publisher1.13.242 of 5See more

dagster dagster 1.13.24

2 of the 5 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
dagster/dagster-celery-k8s:1.13.2494e5e5dd6da0
glibc@2.41-12+deb13u4
no fix listed
dagster/user-code-example:1.13.24206c454797f7
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

2,994
zabbixzabbix-communityVerified publisher7.1.05 of 5See more

zabbix zabbix-community 7.1.0

5 of the 5 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
glibc@2.41-12+deb13u4
no fix listed
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
glibc@2.39-0ubuntu8.6
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
glibc@2.39-0ubuntu8.6
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
glibc@2.39-0ubuntu8.7
no fix listed
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
glibc@2.39-0ubuntu8.6
no fix listed

Open the chart page →

13,791
keycloakcloudpirates-keycloakVerified publisher0.21.412See more

keycloak cloudpirates-keycloak 0.21.41

2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/postgres:18.0073e7c8b84e2
glibc@2.41-12
no fix listed
library/postgres:18.686c951e05bf5
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

fluentdfluent0.6.01 of 1See more

fluentd fluent 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
fluent/fluentd-kubernetes-daemonset:v1.19.3-debian-elasticsearch7-1.1de9cf5f1127a
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,052
netdatanetdataVerified publisher3.7.1741 of 1See more

netdata netdata 3.7.174

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
netdata/netdata:v2.11.121970e176031
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

2,410
connectonepassword-connect2.4.12 of 2See more

connect onepassword-connect 2.4.1

2 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
1password/connect-api:1.8.2e915c0c84397
glibc@2.41-12+deb13u1
no fix listed
1password/connect-sync:1.8.26297ca6136c0
glibc@2.41-12+deb13u1
no fix listed

Open the chart page →

2,610
node-problem-detectordeliveryheroVerified publisher2.4.11 of 1See more

node-problem-detector deliveryhero 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
glibc@2.36-9+deb12u13
no fix listed

Open the chart page →

2,014
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
boky/postfix:v5.1.0aafc77238423
glibc@2.41-12
no fix listed

Open the chart page →

5,716
vaultwardengissilabs1.4.21 of 1See more

vaultwarden gissilabs 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

1,789
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
glibc@2.27-3ubuntu1.6
no fix listed

Open the chart page →

5,601
netboxnetboxOfficialVerified publisher8.3.841 of 5See more

netbox netbox 8.3.84

1 of the 5 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/netbox-community/netbox:v4.7.159e3e5954d02
glibc@2.43-2ubuntu2.4
no fix listed

Open the chart page →

1,077
valkeyvalkeyVerified publisher0.12.01 of 1See more

valkey valkey 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2c123e3715db6
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

858
postgrescloudpirates-postgresVerified publisher0.20.61See more

postgres cloudpirates-postgres 0.20.6

1 container image this version deploys carries CVE-2026-18374.

Container imageDigestPackageFixed in
library/postgres:18.686c951e05bf5
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

openldap-stack-hahelm-openldapVerified publisher4.3.32 of 5See more

openldap-stack-ha helm-openldap 4.3.3

2 of the 5 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
jpgouin/openldap:2.6.9-fixbfdd0088c776
glibc@2.36-9+deb12u9
no fix listed
library/debian:latest9cc080028c43
glibc@2.41-12+deb13u4
no fix listed

Open the chart page →

5,591
zammadzammadOfficialVerified publisher19.0.12See more

zammad zammad 19.0.1

2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
glibc@2.41-12+deb13u3
no fix listed
library/postgres:18.4a02db8cac496
glibc@2.41-12+deb13u3
no fix listed

Open the chart page →

chaos-meshchaos-meshVerified publisher2.8.42 of 4See more

chaos-mesh chaos-mesh 2.8.4

2 of the 4 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.8.40d28dbd95b03
glibc@2.36-9+deb12u14
no fix listed
ghcr.io/chaos-mesh/chaos-dashboard:v2.8.48a8ec8d4c9ea
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

6,667
csi-driver-nfscsi-driver-nfsVerified publisher4.13.41 of 6See more

csi-driver-nfs csi-driver-nfs 4.13.4

1 of the 6 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

3,420
datahubdatahubVerified publisher1.1.43 of 4See more

datahub datahub 1.1.4

3 of the 4 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
acryldata/datahub-actions:v1.7.0.1c5fd70130157
glibc-2.44@2.44-r4
2.44-r6
acryldata/datahub-frontend-react:v1.7.0.199513cc1c45e
glibc-2.44@2.44-r4
2.44-r6
acryldata/datahub-upgrade:v1.7.0.1c3db54d8fb94
glibc-2.44@2.44-r4
2.44-r6

Open the chart page →

750
reflectoremberstackVerified publisher10.0.651 of 1See more

reflector emberstack 10.0.65

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
emberstack/kubernetes-reflector:10.0.6551dbd5880929
glibc@2.39-0ubuntu8.8
no fix listed

Open the chart page →

746
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
glibc@2.35-0ubuntu3.1
no fix listed

Open the chart page →

9,270
rabbitmqcloudpirates-rabbitmqVerified publisher0.21.281 of 2See more

rabbitmq cloudpirates-rabbitmq 0.21.28

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.6-managementde62d9901fb7
glibc@2.39-0ubuntu8.9
no fix listed

Open the chart page →

848
milvusmilvus4.0.312 of 5See more

milvus milvus 4.0.31

2 of the 5 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
glibc@2.31-0ubuntu9.2
no fix listed
milvusdb/milvus:v2.2.13a3a55e1c1497
glibc@2.31-0ubuntu9.7
no fix listed

Open the chart page →

167,022
grafana-agentgrafana0.44.21 of 2See more

grafana-agent grafana 0.44.2

1 of the 2 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
grafana/agent:v0.44.23364714a2f64
glibc@2.39-0ubuntu8.3
no fix listed

Open the chart page →

3,585
mesherymesheryOfficialVerified publisher1.0.701 of 1See more

meshery meshery 1.0.70

1 of the 1 container images this version deploys carry CVE-2026-18374.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest44b64ee128fb
glibc@2.36-9+deb12u14
no fix listed

Open the chart page →

1,500

Container images carrying it

2,750 by charts deploying them

A fixed version is listed for 2 of the 5 affected packages.

No deployed image carries CVE-2026-18374.

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.